1 |
Hello Karl, |
2 |
|
3 |
On Mon, 2003-12-15 at 02:48, Karl Zander wrote: |
4 |
> The Gentoo Security Guide seems to recommend AIDE (Advanced Intrusion |
5 |
> Detection Environment) . And I would like to run that. But given that |
6 |
> files in /bin, /sbin or /etc or other important places that AIDE may be |
7 |
> monitoring can change when running emerge, how management intensive is it |
8 |
> to run AIDE or any other intrusion detection? |
9 |
|
10 |
A production server should not need that many updates, so the effort is |
11 |
reasonable. |
12 |
Check if sth. has changed, emerge, update aide database |
13 |
|
14 |
> I think I read that AIDE was running on the Gentoo rsync server that was |
15 |
> comprised so running it does seem like good practice. |
16 |
|
17 |
IDS means intrusion DETECTION system, not PREVENTION! It cannot prevent |
18 |
you system from being compromized (but a good configuration and regular |
19 |
critical updates can...) - they only help you to understand what |
20 |
happened, e.g. which files have been altered by a rootkit. Same for the |
21 |
NIDS like snort and prelude... |
22 |
|
23 |
HTH |
24 |
Florian Huber |
25 |
|
26 |
-- |
27 |
Florian Huber |
28 |
|
29 |
Key ID: D9D50EA2 |
30 |
Fingerprint: 0241 C329 E355 9B94 8D34 F637 4EB9 1B1D D9D5 0EA2 |
31 |
|
32 |
BOFH Excuse #352: |
33 |
The cables are not the same length. |